Avatar of MSGK161091
MSGK161091
Flag for Australia asked on

Desktop infected with http://search.conduit.com/

Seems I got virus on my desktop , and I need help getting it removed.
While on computer using IE or Mozilla Firefox, I get redirected to the link below which is the most common of re-directions:
http://search.conduit.com/
I know nothing about this site, nor have I ever visited it (willingly).
It says it's powered by Google.
Someone mentioned to me that they checked out SEARCH.CONDUIT (which is included in the link above) and that it is some form of hijacker.
My computer has all the symptoms of an attack by search.conduit

I ran AVAST virus scan (which found nothing), and then I ran MALWAREBYTES ANTI-MALWARE (which nothing showed). First time MALWAREBYTES removed around 6 - 10 infected files but since everytime I run it says no issues found. But I am sure my desktop is under attack.

And also due to which my PC running DAM slow.
Would you please take a look?
Anti-Virus AppsAnti-Spyware

Avatar of undefined
Last Comment
mk3ller

8/22/2022 - Mon
SOLUTION
Lance_P

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
warturtle

Try looking in add/remove programs list, you might find conduit there.

Alternatively, look within the browser extensions and uninstall the un-needed browser extension.

Thanks.
MSGK161091

ASKER
hi
i tried to reset as u said in firefix but still it ooens that site. IE seems ok as i see it opens google as home page
beersince1978

Once you remove malware - it's a good practice to set your automatic updates to be downloaded and installed on weekly basis - this will improve your system immunity to such events. Make sure your browsers are up to date too. Good luck.
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
Lance_P

MSGK161091,
  Goto add remove programs and unsinstall firefox.

Delete any folders from the program files folder.

Reinstall the new version

Make sure you run spybot to clean the registry.
warturtle

Good, now that IE is ok. Let's work on firefox (I have firefox 3.6.15 on my pc, so including instructions from that version):

Tools->Add ons -> locate Conduit within Browser Extensions or Plugins and disable/uninstall.

Restart firefox to see the effect.
SOLUTION
warturtle

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER CERTIFIED SOLUTION
Log in to continue reading
Log In
Sign up - Free for 7 days
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
MSGK161091

ASKER
Hi warturtle

I have checked there is nothing for  Conduit in Add/remove programs nor in brower extenstions.

Hi Lance_p

I am reseting my brower again and this time runing spybot as u suggested, I will let u know.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
younghv

MSGK161091,
Conduit will sometimes be started by a program with a different name.
In addition to the advice above, look through ALL of the programs in the Add/Remove Programs applet and make sure that you know what each one is.

You should also look through your "Programs" folder and do the same check.

Click on the START button, then click on RUN, and type in MSCONFIG. Look through the Startup list and check again.

If you aren't sure what a program is/does, you can do a quick Google search or post the info back here.

What exact OS are you running?
warturtle

Have you tried resetting the browser home page to something else??? It could be that Conduit is already out, but the homepage is still conduit.com, so that opens by default.
MSGK161091

ASKER
Hi Lance_P

I ran spybot , it found few files infected and clean but when I ran again it found and cleaned but page was still opening after I reset firefox and chang homepage to Google. Seems spybot was not hard  enough to remove these

Hi warturtle

I ran EST cleaner and it found 15 threats & removed , which I have attached below . Please have a look.

Hi Younghv

I didn't found any thing in add/remove program neither in any of Program files folder.

Hi Ssharma

I ran OLT as you have said and attached OTL and Extra files here. Please find
threatsfound.ESTCleaner.txt
OTL.Txt
Extras.Txt
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
SOLUTION
Log in to continue reading
Log In
Sign up - Free for 7 days
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
MSGK161091

ASKER
Hi Ssharma

As you have requested, I ran  runfix with the given code by you. please the attachment for the  outcome.
olt-runfixes.txt
Sudeep Sharma

@MSGK161091,

So how's system working right now? Further issues?
MSGK161091

ASKER
Hi Guys
Now my system working fine. no more opening that annoying search page. Happy to be here at EE and part of it. I agree with the  administrative comment that EE experts are qualified and capable to fix the issues, we are not required to go anywhere.  

Thanks guys . Special thanks to  Ssharma/Warturtle.   I believe OLT , as well as EST scanner helped to removed this annoying search conduit page from my system.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
mk3ller

I just removed Conduit.  It had a redirect in the hosts files which I removed.  Also, the browser toolbar was "disguised" in Add/Remove Programs.  It had a generic sounding name which I have already forgotten.  I found it by looking through the list of installed programs and looking for publisher I did not recognize.